- ❌ Never use
any— useunknown+ type guards - ❌ Never use
ascasts without justification - ✅ Use explicit return types on exported functions
- ✅ Use
interfacefor object shapes,typefor unions/intersections
- Use
.jsextensions in imports (ESM):import { foo } from './bar.js' - Absolute imports from
src/for cross-module references
- Validate inputs at route handlers, not deep in business logic
- Use structured error objects, not raw strings
- Redact auth tokens from logs (handled by server middleware)
- Test files go in
src/__tests__/ - Use Vitest
describe/itblocks - Test file naming:
<module>.test.ts - Integration tests should test via HTTP API, not internal functions